Uploaded image for project: 'XWiki Platform'
  1. XWiki Platform
  2. XWIKI-7504

Files within WEB-INF directory readable by using velocity

    XMLWordPrintable

Details

    • Bug
    • Resolution: Fixed
    • Critical
    • 3.5-milestone-1
    • 2.7.2, 3.4
    • Velocity
    • None
    • Tested on 2.7.2 and 3.4, but probably most (all) versions are affected.
    • security, velocity
    • Medium

    Description

      By executing

      {{velocity}}
      #parse('WEB-INF/xwiki.cfg')
      {{velocity}}
      

      it is possible to read files within the WEB-INF folder like e.g. xwiki or hibernate config files.

      We fixed this on our system and you should get a GitHub pull request in the next minutes.

      Attachments

        Activity

          People

            sdumitriu Sergiu Dumitriu
            ebeutler Edoardo Beutler
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: